Tag: data
-
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting”, and vulnerable”, target. First seen on wired.com Jump to article: www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/
-
Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card data and intercept multi-factor authentication (MFA) challenges. Group-IB identified 258 phishing pages linked to the kit since October 2025, with victims across 66 countries. Rather than relying on classic delivery-failure notices, bank alerts, or account-lockout…
-
New Infostealer Can Steal Passwords, Cards, Cookies and Wi-Fi Keys From Windows PCs
A Python-based infostealer builder that enables threat actors to generate customized Windows payloads capable of stealing browser credentials, payment-card data, session cookies, Discord tokens, Wi-Fi passwords and extensive system information. Rather than functioning as a single-use stealer, the package includes a builder interface and an embedded payload, providing a model consistent with Malware-as-a-Service operations. Operators…
-
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/
-
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/
-
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
It has been a bad month for federal government cybersecurity. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/10/hacks-of-2-federal-agencies-in-a-month-have-spilled-a-bonanza-of-sensitive-data/
-
Iranian accused of hacking American universities extradited from Montenegro
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro. First seen on therecord.media Jump to article: therecord.media/iran-montenegro-hacker-extradition
-
OpenAI software attempted to secretly scrape data from dozens of prominent websites
The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software. First seen on therecord.media Jump to article: therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites
-
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.Investigators identified…
-
Logicalis research adds to picture of customer gaps
The ambition is there to protect data, but the ability to do so is different, and it’s opening the door for those with managed security skills First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366651389/Logicalis-research-adds-to-picture-of-customer-gaps
-
The Cyber Express Weekly Roundup: Renfe Confirms Breach, Australia Warns of Hijacked AI Keys, and Europol Sounds the Alarm on AI-Driven Crime
This weekly roundup covers a customer data breach at Spain’s national rail operator, an Australian government warning about attackers hijacking corporate AI services, a patient data theft from a Polish medical software platform, phishing campaigns that turn legitimate remote management tools against their victims, and a gathering of Europe’s police leaders focused on how AI…
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
-
Cyberattack on major Polish invoicing platform exposes customer data
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. First seen on therecord.media Jump to article: therecord.media/poland-cyberattack-invoice-software
-
Pentagon breach exposes personal data of more than 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data. The breach affects 2.76 million living … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/01/pentagon-dmdc-data-breach-3-million-people/
-
Japanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
Times Mobility says a data breach exposed data linked to 6.6 million accounts, including 1.6 million identity records with driver’s license images and documents too. First seen on hackread.com Jump to article: hackread.com/japanese-car-sharing-site-times-car-data-breach/
-
Some car apps are slipping owners’ data to big tech companies
Tags: dataThe app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/01/connected-car-apps-privacy-research/
-
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon’s human resources management system in October 2025. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/
-
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that…
-
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that…
-
OpenAI Accuses Moonshot AI of Coordinated Model Distillation
Campaign Allegedly Used Thousands of Accounts to Extract Hidden Reasoning From OpenAI Models. OpenAI disrupted what it calls a coordinated campaign to extract the training data and reasoning of its AI models, allegedly by the developer of the Kimi model, Chinese company Moonshot AI. The company first noticed the activity in July. First seen on…
-
Automakers routinely share personally identifiable connected-car data with third parties, report says
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem. First seen on therecord.media Jump to article: therecord.media/automakers-routinely-share-connected-car-data-third-parties
-
Hackers stole millions of US military personnel records during months-long data breach
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/30/hackers-stole-millions-of-us-military-personnel-records-during-months-long-data-breach/
-
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,… First seen on hackread.com Jump to article: hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/
-
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,… First seen on hackread.com Jump to article: hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/
-
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol…
-
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol…
-
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular recreation management platform used by local municipalities and parks organisations, planting webshells and going after payment card data. The activity, first observed on 10 September 2026, began noisily. Over roughly six hours the…
-
Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host machine when a user runs the `docker cp` command. This vulnerability affects copy-out operations, where Docker retrieves data from a container and extracts it onto the system running the Docker Command Line Interface…
-
Claude Compliance API Lets Security Teams Monitor Chats, Files and Agent Activity
Anthropic has enhanced enterprise security visibility for its AI assistant, Claude, with the Compliance API. This feature lets organizations extract data on activity, conversations, files, projects, and agent sessions into their existing governance and security operations platforms. The Compliance API is available to both Claude Enterprise and Claude Platform customers, although the breadth of accessible…

